LDAP Password Security

LE BOUTER Leo <[email protected]> Mon, 6 Apr 2020 23:10:31 +0000
Newsgroups gmane.comp.tools.sudo.user
Message-ID <793937D9F3A7EA49BCD7227F32C8138BB446AB@BBS-EXCMBX-P005.wprod.ds.aphp.fr>
Hello,

I am looking to use LDAP with sudo but I am concerned about the idea of every server having access to the user's LDAP password at authentication time.
Is there any alternative ways of authenticating? Considering most if not all my users will reach the server though SSH, is there a way to re-use the GSSAPI/Kerberos facility here?
It would give me greater peace of mind if instead of their password a temporary "kerberos token" specific to their current SSH session was used.

Thanks

Leo Le Bouter
Ingenieur Securite Infrastructure
Entrepot de Donnees de Sante (WIND)
____________________________________________________________
sudo-users mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-users